OT/IT convergence is the integration of operational-technology networks with enterprise IT: shared authentication, shared historians, shared remote access, shared cloud analytics. The motivation is operational, predictive maintenance, real-time telemetry, MES integration, remote expert support. The consequence is that every IT attack path now has at least one reachable route into OT.
What is OT/IT convergence?
For decades, plant-floor OT and corporate IT ran as separate worlds with separate networks, protocols, and owners. Convergence collapses that separation so the two share data and services. The benefits are real, but so is the cost: the air gap that used to protect OT by accident is gone, and the boundary between the two now has to be defended on purpose.
What attack paths does OT/IT convergence create?
Six paths show up again and again in post-incident reviews of converged environments:
1. Active Directory pivot from IT to OT. Engineering workstations authenticate against corporate AD. A credential-theft compromise on the IT side, phishing, Kerberoasting, DCShadow, yields valid credentials that reach OT resources. Colonial Pipeline and Maersk (NotPetya, 2017) both showed this pattern.
2. Historian as a traversal point. Historians sit at Purdue Level 3 and push data up to IT analytics at Level 4. They run standard Windows servers with SQL or InfluxDB backends. An IT-side compromise reaches the historian through its data-egress path, then pivots back down to Level 2 or 1 using the historian's collection credentials.
3. Ransomware traversing via file shares. A shared file server between IT and OT, often hosting G-code, production orders, or machine configs, is an encryption target that halts OT even when OT assets are never touched. Norsk Hydro (2019) followed this shape.
4. Remote-access VPN as a credential single point of failure. A contractor VPN for remote maintenance often grants the same network reach as a local operator. A phished contractor credential becomes a remote PLC session.
5. IIoT gateway lateral movement. IIoT devices installed for predictive maintenance often bridge cellular or Wi-Fi links to OT without passing through the industrial DMZ. Compromise the vendor's cloud platform and it propagates to every deployed gateway.
6. Engineering laptop as a dual-homed bridge. A single workstation on both the corporate and plant networks is a routable path whenever it is online. Most plants have several.
How does an IT ransomware attack reach OT?
A defense manufacturer's IT network is hit with ransomware delivered by a phishing email to HR. It spreads through AD and encrypts file shares. One of those shares is mounted by the MES system at Purdue Level 3. When MES tries to write the next shift's production schedule, the write fails. OT operators at Level 2 lose the work queue. The plant stops, not because OT was compromised, but because OT depended on an IT service that was. That is the convergence incident shape: the attack never touches a PLC, and production halts anyway.
How do you reduce OT/IT convergence risk?
Three structural controls consistently shrink the blast radius:
- Identity isolation between IT and OT. A separate identity provider for OT access, so a compromise of corporate AD does not automatically grant OT access.
- Identity-bound network enforcement. Rules bind to authenticated users and device identities. IT hosts cannot reach OT assets by default, whatever their IP.
- Stateful observation at the convergence points. Historians, file shares, and remote-access gateways get session-level audit, so anomalous patterns are detectable even when an endpoint is already compromised.
Why does OT/IT convergence matter for compliance?
NIS2 Article 21 requires network segmentation and access control for converged environments. IEC 62443 zones-and-conduits explicitly addresses the convergence boundary at the Level 3.5 iDMZ. CMMC Level 2 inherits NIST SP 800-171 Rev 2 control 3.13.1, monitoring and control at key internal boundaries, and the IT/OT boundary is the canonical example.
Related terms
How Access Gate helps
Access Gate enforces identity-bound boundaries across the IT/OT convergence points, historians, file shares, remote access, engineering workstations, so a compromise on the IT side does not open a reachable path into OT. See CMMC Compliance with Trout Access Gates.

